South Korea AI Basic Act (Framework Act on AI Development and Trust)
First comprehensive AI law in Asia: obligations for high-impact AI in employment, healthcare, finance, energy, public safety and education (risk management, impact assessment, human oversight), mandatory labelling of generative AI output, and a domestic representative requirement for foreign providers. Enforcement Decree in force 22 January 2026.
| Jurisdiction | South Korea |
|---|---|
| Category | AI Regulations |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
South Korea’s AI Basic Act (Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust) is a comprehensive AI law that entered into force on 22 January 2026, together with its Enforcement Decree (Presidential Decree No. 36053).South Korea: Comprehensive AI Legal Framework Takes Effect – Library of CongressFramework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust – English translation (KLRI)Enforcement Decree Explorer – AI Basic Act
Below is a structured, requirement‑by‑requirement analysis with direct links to primary legal texts and key official/industry sources.
Key Requirements
1. Scope and High‑Impact AI Sectors
- The Act establishes a national framework for AI development and trust, covering promotion, risk management, and user protection for AI systems.Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust – KLRISouth Korea: Comprehensive AI Legal Framework Takes Effect – Library of Congress
- “High‑impact AI” systems are singled out for stricter obligations, including those used in employment, medical/healthcare, finance, energy, public safety, and education, through risk‑based obligations and designation criteria in the Enforcement Decree.Enforcement Decree Explorer – AI Basic ActSouth Korea AI Regulation Tracker – DeepLexAI Watch: Global Regulatory Tracker – South Korea (JDSupra)
2. Risk Management and Impact Assessment for High‑Impact AI
- Providers and certain operators of high‑impact AI must implement risk management measures, including identification, analysis and mitigation of risks, particularly where AI may significantly affect rights, safety or livelihoods.Framework Act – KLRI (Articles on trustworthy AI and user protection)South Korea: Comprehensive AI Legal Framework Takes Effect – Library of Congress
- The Enforcement Decree specifies detailed obligations, including procedures for AI risk assessments / impact assessments for designated high‑impact use cases (e.g., employment screening, credit scoring, health diagnostics, public safety systems). These assessments typically cover impacts on fundamental rights, discrimination, safety and security.Enforcement Decree Explorer – AI Basic ActSouth Korea AI Regulation – DeepLex
- According to legal analyses, impact assessment results must inform mitigation and oversight, and may be subject to reporting or disclosure obligations to regulators depending on the sector and risk level.South Korea’s AI Basic Act: Overview and Key Takeaways – CooleyRecent Developments in AI Basic Act – Kim & Chang
3. Human Oversight and Accountability
- The Act requires human involvement/oversight over high‑impact AI systems, aiming to prevent fully automated decisions without appropriate human review where rights or safety could be significantly affected.Framework Act – KLRISouth Korea: Comprehensive AI Legal Framework Takes Effect – Library of Congress
- The Enforcement Decree details oversight requirements such as ensuring the ability to intervene, halt AI operation, or correct outcomes in high‑risk scenarios, and aligning organizational governance to assign responsible persons.Enforcement Decree Explorer – AI Basic ActSouth Korea AI Regulation – DeepLex
4. Mandatory Labelling / Disclosure of Generative AI Output
- The AI Basic Act introduces mandatory labeling/disclosure requirements for AI‑generated content, particularly for generative AI systems that produce text, images, audio, or video.South Korea: Comprehensive AI Legal Framework Takes Effect – Library of CongressAI Watch: Global Regulatory Tracker – South Korea (JDSupra)
- Legal commentary notes that providers of generative AI services must inform users when content is AI‑generated, potentially through visible marks, notices, or metadata, as specified in subordinate regulations and MSIT guidance.South Korea’s AI Basic Act: Overview and Key Takeaways – CooleyRecent Developments in AI Basic Act – Kim & Chang
5. Domestic Representative Requirement for Foreign AI Providers
- The framework imposes a domestic representative / local point of contact requirement on certain foreign AI providers offering AI services in Korea, to ensure enforceability and communication with authorities and users.AI Watch: Global Regulatory Tracker – South Korea (JDSupra)South Korea AI Regulation – DeepLex
- Legal analyses compare this to the EU GDPR and EU AI Act representative concepts, noting that foreign providers may need to appoint a legal representative or establish a local entity depending on their activities and risk profiles.South Korea’s AI Basic Act: Overview and Key Takeaways – CooleyRecent Developments in AI Basic Act – Kim & Chang
6. Governance, Basic Plan and Certification / Notice Systems
- The Act mandates that the government formulate an AI Basic Plan, including promotion measures, risk management policies, and standards for trustworthy AI.Framework Act – KLRIPress release: “The AI Basic Act Comes into Force” – MSIT
- The Enforcement Decree details procedures for establishing and revising the AI Basic Plan and for supporting AI R&D projects and trust‑building initiatives.Enforcement Decree of the Framework Act – TUV summaryEnforcement Decree Explorer – AI Basic Act
- The Act also provides for notice and certification systems to promote trustworthy AI (e.g., labeling or certifying AI that meets certain reliability and safety criteria).South Korea: Comprehensive AI Legal Framework Takes Effect – Library of CongressAI Watch: Global Regulatory Tracker – South Korea (JDSupra)
Compliance Challenges
1. Interpreting “High‑Impact AI” and Sector‑Specific Thresholds
- Organizations report difficulty determining whether their AI falls into “high‑impact” categories, especially in borderline cases (e.g., HR analytics vs. automated hiring decisions; clinical decision support vs. diagnostic systems).South Korea AI Regulation – DeepLexRecent Developments in AI Basic Act – Kim & Chang
- Legal practitioners note challenges where AI systems are multi‑purpose or cross‑sector, requiring mapping to multiple regulatory regimes (e.g., employment law, financial regulation, medical device rules).South Korea’s AI Basic Act: Overview and Key Takeaways – CooleyAI Watch: Global Regulatory Tracker – South Korea (JDSupra)
2. Building Risk / Impact Assessment Capabilities
- Many companies lack internal expertise to conduct formal AI risk or impact assessments, particularly in smaller entities or firms newly adopting AI.Recent Developments in AI Basic Act – Kim & ChangSouth Korea AI Regulation – DeepLex
- Reports comparing global AI regimes highlight resource constraints and data limitations in assessing algorithmic bias, safety and robustness.AI Watch: Global Regulatory Tracker – South Korea (JDSupra)South Korea’s AI Basic Act – Cooley
3. Generative AI Labeling and UX Integration
- Organizations offering generative AI services face practical challenges in implementing labeling, such as designing clear user notices in multi‑modal interfaces and ensuring that downstream users do not remove or obscure AI‑generation markings.South Korea: Comprehensive AI Legal Framework Takes Effect – Library of CongressSouth Korea’s AI Basic Act – Cooley
- Industry analyses note difficulties aligning labeling obligations with existing content workflows, especially where content is edited, combined or translated after AI generation.AI Watch: Global Regulatory Tracker – South Korea (JDSupra)South Korea AI Regulation – DeepLex
4. Foreign Providers and Domestic Representative
- Foreign AI service providers must understand when a domestic representative is required, how to structure that relationship, and what liabilities and obligations attach to the representative.AI Watch: Global Regulatory Tracker – South Korea (JDSupra)South Korea’s AI Basic Act – Cooley
- Cross‑border compliance reports highlight coordination challenges between AI Basic Act requirements and Korean data protection, telecoms, and sectoral regulations (e.g., financial services, medical devices).Recent Developments in AI Basic Act – Kim & ChangSouth Korea: Comprehensive AI Legal Framework Takes Effect – Library of Congress
Implementation Best Practices
1. Establish AI Governance and Inventory
- Create an AI inventory of systems used in employment, healthcare, finance, energy, public safety and education, identifying those likely to be “high‑impact” under the Act.Framework Act – KLRISouth Korea AI Regulation – DeepLex
- Formalize AI governance structures (e.g., AI steering committee, accountable executive, clear roles for compliance, risk, IT, product) aligned with the Act’s trustworthiness and user protection objectives.South Korea’s AI Basic Act – CooleyRecent Developments in AI Basic Act – Kim & Chang
2. Implement Structured Risk / Impact Assessment
- Adopt risk assessment frameworks inspired by global standards (e.g., NIST AI Risk Management Framework) and adapt them to Korean requirements for high‑impact AI.NIST AI Risk Management FrameworkAI Watch: Global Regulatory Tracker – Global context (JDSupra)
- For high‑impact systems, implement documented AI impact assessments covering data sources, model behavior, bias and discrimination risks, safety and security, human oversight, and alignment with sector‑specific rules.Enforcement Decree Explorer – AI Basic ActSouth Korea AI Regulation – DeepLex
3. Design Human‑in‑the‑Loop Oversight
- Define clear escalation and override procedures: human reviewers who can intervene, suspend, or correct AI decisions in high‑impact domains.Framework Act – KLRISouth Korea: Comprehensive AI Legal Framework Takes Effect – Library of Congress
- Align design with recognized governance practices, integrating human‑in‑the‑loop or human‑on‑the‑loop patterns documented in international AI governance guidance.NIST AI Risk Management FrameworkOECD AI Principles and governance guidance
4. Implement Generative AI Labeling and Transparency
- Embed automatic labeling of AI‑generated content at the UI level (e.g., “Generated by AI” badges) and at metadata level where feasible, consistent with the Act’s labeling obligations.South Korea: Comprehensive AI Legal Framework Takes Effect – Library of CongressSouth Korea’s AI Basic Act – Cooley
- Integrate user education and consent flows explaining the use of AI, limitations, and labeling, aligned with global transparency practices.AI Watch: Global Regulatory Tracker – South Korea (JDSupra)OECD AI Principles – transparency guidance
5. Tools and Resources
- Use the AI Basic Act Enforcement Decree Explorer
Recent developments
- — A revised version of South Korea’s **AI Basic Act** (Framework Act on Fostering and Establishing a Trust-based Environment for AI) took effect on July 21, 2026, triggering **mandatory labeling of generative AI content** and strengthening obligations for high‑risk AI systems.[6] (source)
- — Reports note that the AI Basic Act has been in force since January 22, 2026, and the government is pairing the new AI rules with a **state-backed free chatbot service**, which has influenced user behavior with tens of millions reportedly switching away from paid foreign AI services.[4] (source)
- — Analysis describes the AI Basic Act as the **world’s first comprehensive national AI legal framework**, effective January 22, 2026, aiming to balance industry innovation with social risk mitigation through obligations on transparency, accountability, and risk management.[13] (source)
- — A regulatory tracker update explains that the AI Basic Act, passed in December 2024 and in force since January 22, 2026, establishes **stringent notice, labeling, and certification requirements** intended both to promote the AI industry and to protect users in South Korea.[12] (source)
- — A legal monitor note confirms that on January 22, 2026, South Korea’s comprehensive AI regulatory framework—Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trust—and its **Enforcement Decree** formally took effect, creating a detailed national AI compliance regime.[8] (source)
- — International coverage describes South Korea’s AI Basic Act as “world‑first” AI regulation, noting requirements to **label AI‑generated content and conduct risk assessments for high‑impact AI**, while startups criticize the law as overly burdensome and civil society groups argue it does not go far enough.[3] (source)
- — Coverage of implementation day highlights that the AI Basic Act now **mandates watermarks or labels on generative AI content** and introduces a one‑year grace period before fines are imposed, while many corporations fear the new obligations could hinder domestic AI development.[11] (source)
- — News on the “landmark” AI laws notes that South Korea’s AI Basic Act took effect on January 22, 2026, with authorities promising at least a **one‑year grace period** on administrative fines, even as startups warn that compliance burdens and documentation requirements will be heavy.[5] (source)
- — An announcement from the Ministry of Science and ICT states that the **AI Basic Act and its Enforcement Decree** entered into force on January 22, 2026, formally laying the foundation for the AI industry while aiming to enhance national competitiveness and a safe, trustworthy AI environment.[7] (source)
- — An article days before implementation reports **industry backlash** against the AI Basic Act, with critics warning that vague provisions, extensive prior notification and labeling duties, and safety obligations—especially for generative and high‑impact AI—could hamper sector growth amid widespread unpreparedness.[10] (source)
Related regulations
- Brazilian Artificial Intelligence Act — Brazil, Proposed
- NIST AI Risk Management Framework (AI RMF 1.0) — United States, Active, effective 2023-01-26
- Artificial Intelligence and Data Act — Canada, Superseded
- Colorado Artificial Intelligence Act (SB 24-205) — Colorado, Superseded, effective 2026-06-30
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) — Texas, Active, effective 2026-01-01
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
- EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — European Union, Active, effective 2026-07-27
Put it into practice
- Generate the policy: NIST AI RMF policy generator (generatepolicy.com)
- Buy the policy pack: NIST AI RMF Implementation Policy (cyberpolicy.shop)
- Build it yourself: Pillar 06 Companion — The 2026 AI Risk Register (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates